kevmap

TechniquesT1199 › AN1347

AN1347 Analytic 1347

Identity Provider · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Behavioral chain: (1) delegated admin or external identity establishes session (e.g., partner/reseller DAP, B2B guest, SAML/OAuth trust); (2) role elevation or app consent/permission grant; (3) downstream privileged actions in the tenant. Correlate IdP sign-in, admin/role assignment, and consent/admin-on-behalf events.</p>
Detects
T1199 Trusted Relationship
Part of
DET0488 Detect abuse of Trusted Relationships (third-party and delegated admin access)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
azure:signinlogsInteractiveUser, ServicePrincipalSignInDC0067 Logon Session Creation
azure:auditAdd delegated admin / Assign admin roles / Update application consentDC0088 Logon Session Metadata
m365:unifiedSet-PartnerOfRecord / CompanyAdministrator role assignments / New-DelegatedAdminRelationshipDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TrustedPartnerTenantIDsTenant IDs of approved partners; any others are suspicious.
RequiredMFARequire MFA for partner sessions; alert on bypass or step-up failure.
RoleScopeAllowListRoles third-parties may hold (e.g., Helpdesk Admin); flag broader scopes.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2024-53704SonicWall SonicOSMapped